SCS-C02 · Question #215
A company is storing data in Amazon S3 Glacier. A security engineer implemented a new vault lock policy for 10 TB of data and called the initiate-vault-lock operation 12 hours ago. The audit team…
The correct answer is A. Call the abort-vault-lock operation. Update the policy. Call the initiate-vault-lock operation again. The most cost-effective way to correct a typo in a vault lock policy during the 24-hour initiation period is to call the abort-vault-lock operation. This action stops the vault lock process, allowing the security engineer to correct the policy and re-initiate the vault lock…
Question
A company is storing data in Amazon S3 Glacier. A security engineer implemented a new vault lock policy for 10 TB of data and called the initiate-vault-lock operation 12 hours ago. The audit team identified a typo in the policy that is allowing unintended access to the vault. What is the MOST cost-effective way to correct this error?
Options
- ACall the abort-vault-lock operation. Update the policy. Call the initiate-vault-lock operation again.
- BCopy the vault data to a new S3 bucket. Delete the vault. Create a new vault with the data.
- CUpdate the policy to keep the vault lock in place
- DUpdate the policy. Call the initiate-vault-lock operation again to apply the new policy.
How the community answered
(26 responses)- A77% (20)
- B4% (1)
- C12% (3)
- D8% (2)
Explanation
The most cost-effective way to correct a typo in a vault lock policy during the 24-hour initiation period is to call the abort-vault-lock operation. This action stops the vault lock process, allowing the security engineer to correct the policy and re-initiate the vault lock with the corrected policy. This approach avoids the need for data transfer or creating a new vault, thus minimizing costs and operational overhead.
Topics
Community Discussion
No community discussion yet for this question.